Quora

Staff Product Security Software Engineer (Remote)

United States

Not SpecifiedCompensation
Junior (1 to 2 years)Experience Level
Full TimeJob Type
UnknownVisa
Internet, Social Media, AI & Machine LearningIndustries

Position Overview

  • Location Type: Remote
  • Job Type: Full-Time
  • Salary: Not Specified

Quora is a "remote-first" company. This position can be performed remotely from multiple countries around the world. Please visit careers.quora.com/eligible-countries for details regarding employment eligibility by country.

About Quora: Quora’s mission is to grow and share the world’s knowledge. To do so, we have two knowledge sharing products:

  • Quora: a global knowledge sharing platform with over 400M monthly unique visitors, bringing people together to share insights on various topics and providing a unique platform to learn and connect with others.
  • Poe: a platform providing millions of global users with one place to chat, explore and build with a wide variety of AI language models (bots), including GPT-4, Claude 3, Gemini Pro, DALL-E 3 and more. As AI capabilities rapidly advance, Poe provides a single platform to instantly integrate and utilize these new models.

Behind these products are passionate, collaborative, and high-performing global teams. We have a culture rooted in transparency, idea-sharing, and experimentation that allows us to celebrate success and grow together through meaningful work. Join us on this journey to create a positive impact and make a significant change in the world.

This role will be working on both Quora and Poe.

About the Team and Role: You will be a key member of the newly created Security Engineering Team, with a mission to keep Quora safe from security problems by building robust protections around our products, infrastructure and people. Our small engineering team works on challenging problems every day. We have a culture that's rooted in constantly learning and improving, and our engineers are encouraged to think big and experiment with new ideas.

What We’re Looking For:

  • Sweat The Right Details: you thrive in understanding the details but will also know to ruthlessly prioritize the critical issues.
  • Right-Size The Solution: you recognize guidelines and framework do not always fit the problem and know how to adjust the solution for scalability not always at-scale.
  • Ownership: you are outcome focused and can deftly navigate obstacles, decompose complexities, manage your time and can communicate your vision to peers and management.

An Ideal Candidate Would…

  • Be a capable software engineer while also possessing the following domain expertise:
    • Secure Web Application Development: You are proficient in developing secure web applications and APIs, with a strong understanding of OWASP Top 10 and other common web vulnerabilities such as XSS, CSRF, SQL Injection, and clickjacking. You have experience implementing mitigations such as Content Security Policies (CSP), SameSite cookies, and secure HTTP headers. You are adept at building secure authentication and authorization mechanisms, including OAuth, OpenID Connect, SAML, and JWTs.
    • Client-Side Security: You have expertise in improving the security posture of client-side web applications. You understand the nuances of browser extensions, sandboxing, and JavaScript security. You are knowledgeable about secure JavaScript frameworks. You can identify and mitigate attacks like DOM-based XSS and other client-side vulnerabilities.
    • Cross-Browser Compatibility and Privacy: You are familiar with the intricacies of cross-browser compatibility and the security implications of browser-specific features. You are passionate about advancing privacy-respecting features in web applications, such as implementing proper cookie handling, using privacy-preserving APIs, and reducing fingerprinting risks. You follow developments in browser security policies like SameSite, Secure, and HttpOnly cookies.
    • Performance and Security Tradeoffs: You understand the fine balance between performance optimization and security requirements in web applications. You can implement advanced security measures, You are skilled in analyzing and mitigating the impact of security features on page load times, caching, and scalability.
    • Security Testing and To (Incomplete sentence)

Application Instructions

Not Specified

Company Information

Quora

Skills

Security Engineering
Product Security
Infrastructure Security
Security Protections
Problem-Solving
Prioritization
Frameworks and Guidelines

Quora

Global knowledge sharing and AI integration platform

About Quora

Quora is a global platform for knowledge sharing that attracts over 400 million unique visitors each month. It allows users to share insights on a wide variety of topics, creating a community focused on learning and connection. Users include individuals looking for information, experts sharing their knowledge, and businesses engaging with a knowledgeable audience. Quora also features Poe, a platform that combines several AI language models like GPT-4 and DALL-E 3, enabling users to chat and explore these technologies in one place. Unlike many competitors, Quora's business model relies on targeted advertising to its large user base, allowing it to continuously expand its offerings to meet user needs.

Mountain View, CaliforniaHeadquarters
2009Year Founded
$351.2MTotal Funding
LATE_VCCompany Stage
Consumer Software, AI & Machine Learning, EducationIndustries
1,001-5,000Employees

Benefits

Health Insurance
Dental Insurance
Vision Insurance
Company Equity
Remote Work Options
Unlimited Paid Time Off
Mental Health Support

Risks

Increased competition from Reddit and Stack Exchange could dilute Quora's user base.
AI-generated content may lead to misinformation without proper oversight.
Privacy concerns over data collection for ads could lead to regulatory scrutiny.

Differentiation

Quora integrates AI models like GPT-4 and DALL-E 3 through its Poe platform.
Quora's Writing Sessions offer a unique alternative to Reddit's AMA for expert Q&A.
Quora's partnership with Bombora enhances B2B audience targeting for advertisers.

Upsides

Quora attracts over 400 million unique visitors monthly, boosting its advertising potential.
AI-driven content moderation can improve user experience by reducing misinformation.
Personalized learning experiences through AI can enhance user retention and satisfaction.

Land your dream remote job 3x faster with AI